|
EAP-MD5 |
LEAP |
EAP-TLS |
EAP-TTLS |
PEAP |
|
|
Server Authentication |
None |
Password Hash |
Public Key (Certificate) |
Public Key (Certificate) |
Public Key (Certificate) |
|
Supplicant Authentication |
Password Hash |
Password Hash |
Public Key (Certificate or Smart Card) |
CHAP, PAP, MS-CHAP(v2), EAP |
Any EAP, like EAP-MS-CHAPv2 or Public Key |
| Authentication Attributes | One -Way Authentication | Mutual Authentication | Mutual Authentication | Mutual Authentication | Mutual Authentication |
|
Dynamic Key Delivery |
No |
Yes |
Yes |
Yes |
Yes |
| Deployment Difficulty | Easy | Moderrate | Hard | Moderrate | Moderrate |
|
Security Risks |
Identity exposed, Dictionary attack, Man-in-the-Middle (MitM) attack, Session hijacking |
Identity exposed, Dictionary attack |
Identity exposed |
MitM attack |
MitM attack; Identity hidden in Phase 2 but potential exposure in Phase 1 |